
On older versions of Windows, Microsoft Defender Offline is still called by its old name: Windows Defender Offline. Check out the post “Windows Defender Offline” in Windows 10 Eliminates Complex Malware for more information. There is also no explanation of the Abandoned status in the documentation.Update: Microsoft Defender Offline is a built-in feature in Windows 10 - no need to create a Windows Defender Offline bootable media. Other than the unhelpful message provided in the event log and the documentation, what actually does the Windows Defender Event Id 5007 mean? Do I have something to worry? Given the information, would you know why that is? It appears that the Windows Defender Offline process did not run at all. One has the status of Abandoned with the header Remediation Incomplete. Windows Defender reported it was infected, so I immediately removed the pen drive and returned it to its owner without opening any of its files.īoth, a Quick Scan and a Full Scan report 0 threats found but the Protection History shows 3 Severe entries, two of which were Quanrantined and removed. I ask this because I am a bit worried about a pen drive I recently inserted into the USB interface of my computer to copy some songs from. I also checked the log files in the C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service folder but they are not helpful in indicating what actually happened, and esp. If these event Ids are not in the event log, then it means that the Windows Defender Offline process did not run. New value: HKLM\SOFTWARE\Microsoft\Windows Defender\IsServiceRunning = 0x1įrom what I read, event Id 1000 means that the offline scan started, and event Id 1001 means that it completed. Old value: Default\IsServiceRunning = 0x0 Unexpected event you should review the settings as this may be the result Windows Defender Antivirus Configuration has changed. Windows Defender Antivirus downloaded and configured Windows Defender

I checked the Event Viewer and it reports two Information messages only and no errors. I can't even tell if the thing actually ran. When I start the Offline scan from the Windows Defender App in Windows 10, as expected, it restarts my system and then only briefly attempts to run Windows Defender Offline but quickly restarts my system again in only 2 - 3 seconds or so instead of the 15 minutes or so it reports that it usually takes.
